Kinsing is a Go-based remote-access trojan used in H2Miner cryptocurrency-mining operations against Linux servers and containerized infrastructure, including Docker environments and Kubernetes clusters. It communicates with command-and-control servers over HTTP, executes received commands, downloads and launches additional payloads, and deploys and supervises cryptocurrency miners, including XMRig configured to mine Monero.
Kinsing operators compromise internet-facing applications through remote-code-execution vulnerabilities and abuse exposed or insecurely configured services. Observed entry points include unauthenticated Docker daemon APIs, Redis services without adequate authentication, and permissively configured PostgreSQL containers. Exploitation campaigns have targeted Apache HTTP Server, Oracle WebLogic, Confluence, CouchDB, Openfire, and ActiveMQ, among other products. Documented vulnerabilities include CVE-2021-41773, CVE-2021-44228, CVE-2022-24706, CVE-2022-26134, CVE-2023-32315, and CVE-2023-46604. Shell scripts commonly retrieve and execute Kinsing after successful compromise.
Kinsing discovers additional hosts by examining local host mappings and SSH connection records, searches for private keys, and uses valid SSH credentials to access remote systems. It also uses masscan to identify additional targets and collects host characteristics for command-and-control communication. Associated installation scripts establish persistence through cron and systemd, terminate competing miners, interfere with security agents and firewall controls, and clear shell history. Deployments have included an accompanying shared-library rootkit. Its principal operational objective is hijacking computing resources for cryptocurrency mining, particularly on exposed Linux and cloud-hosted infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2019-0193 Solr dataimport RCE
During routine sandbox hunting analysis, the Uptycs Threat Research team uncovered evidence of an ongoing live campaign exploiting the Log4j vulnerability, which commenced in January 2024.
CVE-2017-15718 Hadoop Yarn REST API Unauthorized RCE
CVE-2019-3396 Confluence Unauthorized RCE
CVE-2020-25213 WordPress File Manager RCE
CVE-2017-9841 Arbitrary PHP execution
CVE-2021-26084 Confluence Server Webwork OGNL injection
CVE-2018-20062 ThinkPHP 5.X RCE
CVE-2019-19781 Citrix Application Delivery Controller and Citrix Gateway RCE
The people behind it use high severity, public vulnerabilities to continue installing their RAT and miner, such as the recent Apache Path Traversal CVE-2021-41773.
CVE-2023-46604 allows remote attackers with network access to a broker to execute arbitrary shell commands. This is achieved by exploiting serialized class types within the OpenWire protocol, which, in turn, leads to the broker instantiating any class available on the classpath.
CVE-2020-11651(2) SaltSTack 3000.1 RCE
These attackers are also known ... for exploiting several vulnerabilities: CVE-2017-11610 Supervisor 3.0a1 – 3.3.2 RCE.
On June 2, Atlassian published an advisory for CVE-2022-26134, a critical zero-day remote code execution vulnerability in Confluence Server and Data Center.
The table lists CVE-2023-32315 for Openfire. The discussion of Kinsing states that recent Openfire and RocketMQ vulnerabilities were exploited within one to two weeks after disclosure.
Attackers have been actively exploiting this vulnerability since a public exploit was available (May 11th), installing the Kinsing malware family for cryptocurrency mining.
In 2020 Oracle disclosed a series of high severity vulnerabilities, allowing remote code execution (CVE-2020-14882, CVE-2020-14750, and CVE-2020-14883). Recently, we identified a widespread campaign of Kinsing that targeted vulnerable versions of WebLogic servers. | Kinsing is a known malware that targets Linux environments for cryptocurrency purposes. Kinsing uses some unique techniques that target containerized environments, making it also common in Kubernetes clusters.
In 2020 Oracle disclosed a series of high severity vulnerabilities, allowing remote code execution (CVE-2020-14882, CVE-2020-14750, and CVE-2020-14883). Attacks start with scanning of a wide range of IP addresses, looking for an open port that matches the WebLogic default port (7001). | Kinsing is a known malware that targets Linux environments for cryptocurrency purposes. Kinsing uses some unique techniques that target containerized environments, making it also common in Kubernetes clusters.
In 2020 Oracle disclosed a series of high severity vulnerabilities, allowing remote code execution (CVE-2020-14882, CVE-2020-14750, and CVE-2020-14883). If vulnerable, attackers can use one of the exploits to run their malicious payload (Kinsing in this case). | Kinsing is a known malware that targets Linux environments for cryptocurrency purposes. Kinsing uses some unique techniques that target containerized environments, making it also common in Kubernetes clusters.
CVE-2020-11651(2) SaltSTack 3000.1 RCE
The content notes that actors behind Kinsing have recently exploited CVE-2023-4911 (Looney Tunables) as another high-profile vulnerability. | Active exploitation of Apache ActiveMQ CVE-2023-46604 was used to download and infect Linux systems with Kinsing. Once executed, it downloads additional binaries, establishes cron-based persistence, removes competing miners, and loads a rootkit through /etc/ld.so.preload.
We have previously published a blog on what organizations need to know about the actively exploited CVE-2025-55182, which is a critical (CVSS 10.0) pre-authentication remote code execution vulnerability affecting React Server Components (RSC) used in React.js, Next.js, and related frameworks. | The script kills competing malware and legitimate processes, downloads and executes a cryptominer and KINSING from 78.153.140[.]16, establishes persistence via systemd services and cron jobs and attempts to hide its tracks by clearing the bash history.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Their ultimate purpose remains consistent: deploying Kinsing, a remote access trojan (RAT) commonly used to deliver crypto miners in compromised environments.
«Скрипт загружает и запускает вредоносный бинарный файл kinsing — известный майнер и backdoor, активно использующий уязвимые Docker-хосты для распространения».
Most notably, TeamTNT was reported to have copied the code used to detect and remove Alibaba Cloud Security from compromised instances from the Kinsing group.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
establishes persistence by installing it across multiple layers: as a systemd service (if root), as a crontab @reboot job
Kinsing adds a cronjob to download and execute its malicious bootstrap script every minute.
Kinsing actively looks for competing cryptocurrency miners ... in processes, crontabs, and active network connections. It then proceeds to kill their processes and network connections.
183 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
99 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as the botnet associated with a competing miner that RedTail removes from infected hosts.
Linux-focused cryptocurrency-mining malware that exploits vulnerable web applications and misconfigured container environments for access. It downloads architecture-specific payloads, mines cryptocurrency using host resources, removes competing miners, creates a cron job that re-downloads its bootstrap script every minute, and loads a rootkit via /etc/ld.so.preload for deeper persistence.
Cryptomining malware deployed as a follow-on payload; it establishes persistence, disables defenses, removes competitors, and attempts deeper hooks via /etc/ld.so.preload.
Known Linux cryptominer malware referenced as an example of commodity malware detectable via signatures such as YARA rules or hash matching.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.